profile.module 28.2 KB
Newer Older
Dries's avatar
   
Dries committed
1
<?php
Dries's avatar
Dries committed
2
// $Id$
Dries's avatar
   
Dries committed
3

Dries's avatar
   
Dries committed
4
5
6
7
8
/**
 * @file
 * Support for configurable user profiles.
 */

9
10
11
12
13
14
/**
 * Flags to define the visibility of a profile field.
 */
define('PROFILE_PRIVATE', 1);
define('PROFILE_PUBLIC', 2);
define('PROFILE_PUBLIC_LISTINGS', 3);
15
define('PROFILE_HIDDEN', 4);
16

Dries's avatar
   
Dries committed
17
18
19
/**
 * Implementation of hook_help().
 */
Dries's avatar
   
Dries committed
20
function profile_help($section) {
Dries's avatar
   
Dries committed
21
  switch ($section) {
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
    case 'admin/help#profile':
      $output = '<p>'. t('The profile module allows you to define custom fields (such as country, real name, age, ...) in the user profile.  This permits users of a site to share more information about themselves, and can help community-based sites to organize users around profile fields.') .'</p>';
      $output .= t('<p>The following types of fields can be added to the user profile:</p>
<ul>
<li>single-line textfield</li>
<li>multi-line textfield</li>
<li>checkbox</li>
<li>list selection</li>
<li>freeform list</li>
<li>URL</li>
<li>date</li>
</ul>
');
      $output .= t('<p>You can</p>
<ul>
<li>view user <a href="%profile">profiles</a>.</li>
<li>administer profile settings: <a href="%admin-settings-profile">administer &gt;&gt; settings &gt;&gt; profiles</a>.</li>
</ul>
', array('%profile' => url('profile'), '%admin-settings-profile' => url('admin/settings/profile')));
      $output .= '<p>'. t('For more information please read the configuration and customization handbook <a href="%profile">Profile page</a>.', array('%profile' => 'http://www.drupal.org/handbook/modules/profile/')) .'</p>';
      return $output;
Dries's avatar
   
Dries committed
43
    case 'admin/modules#description':
44
      return t('Supports configurable user profiles.');
45
    case 'admin/settings/profile':
46
      return t('<p>Here you can define custom fields that users can fill in in their user profile (such as <em>country</em>, <em>real name</em>, <em>age</em>, ...).</p>');
Dries's avatar
   
Dries committed
47
48
49
  }
}

50
51
52
53
54
55
56
57
58
59
60
61
62
/**
 * Implementation of hook_block().
 */
function profile_block($op = 'list', $delta = 0, $edit = array()) {

  if ($op == 'list') {
     $blocks[0]['info'] = t('Author information');

     return $blocks;
  }
  else if ($op == 'configure' && $delta == 0) {
    // Compile a list of fields to show
    $fields = array();
63
    $result = db_query('SELECT name, title, weight FROM {profile_fields} ORDER BY weight');
64
65
66
67
    while ($record = db_fetch_object($result)) {
      $fields[$record->name] = $record->title;
    }
    $fields['user_profile'] = t('Link to full user profile');
68
    $form['profile_block_author_fields'] = array('#type' => 'checkboxes', '#title' => t('Profile fields to display'), '#default_value' => variable_get('profile_block_author_fields', NULL), '#options' => $fields, '#description' => t('Select which profile fields you wish to display in the block.  Only fields designated as public in the <a href="%profile-admin">profile field configuration</a> are available.', array('%profile-admin' => url('admin/settings/profile'))));
69
    return $form;
70
71
72
73
74
75
76
  }
  else if ($op == 'save' && $delta == 0) {
    variable_set('profile_block_author_fields', $edit['profile_block_author_fields']);
  }
  else if ($op == 'view') {
    if (user_access('access user profiles')) {
      if ((arg(0) == 'node') && is_numeric(arg(1)) && (arg(2) == NULL)) {
77
        $node = node_load(arg(1));
78
79
80
81
82
        $account = user_load(array('uid' => $node->uid));

        if ($use_fields = variable_get('profile_block_author_fields', array())) {
          // Compile a list of fields to show
          $fields = array();
83
84
85
86
          $result = db_query('SELECT name, title, type, visibility, weight FROM {profile_fields} WHERE visibility IN (%d, %d) ORDER BY weight', PROFILE_PUBLIC, PROFILE_PUBLIC_LISTINGS);
          while ($record = db_fetch_object($result)) {
            // Ensure that field is displayed only if it is among the defined block fields and, if it is private, the user has appropriate permissions.
            if (in_array($record->name, $use_fields)) {
87
88
89
90
91
92
              $fields[] = $record;
            }
          }
        }

        if ($fields) {
93
          $fields = _profile_update_user_fields($fields, $account);
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
          $output .= theme('profile_block', $account, $fields, true);
        }

        if (in_array('user_profile', $use_fields)) {
          $output .= '<div>' . l(t('View full user profile'), 'user/' . $account->uid) . '</div>';
        }
      }

      if ($output) {
         $block['subject'] = t('About %name', array('%name' => $account->name));
         $block['content'] = $output;
         return $block;
      }
    }
  }
}

Dries's avatar
   
Dries committed
111
/**
Dries's avatar
   
Dries committed
112
 * Implementation of hook_menu().
Dries's avatar
   
Dries committed
113
 */
Dries's avatar
   
Dries committed
114
function profile_menu($may_cache) {
115
  global $user;
Dries's avatar
   
Dries committed
116
  $items = array();
Dries's avatar
   
Dries committed
117
118
119
120

  if ($may_cache) {
    $items[] = array('path' => 'profile', 'title' => t('user list'),
      'callback' => 'profile_browse',
121
      'access' => user_access('access user profiles'),
Dries's avatar
   
Dries committed
122
      'type' => MENU_SUGGESTED_ITEM);
123
    $items[] = array('path' => 'admin/settings/profile', 'title' => t('profiles'),
124
      'callback' => 'profile_admin_overview');
125
    $items[] = array('path' => 'admin/settings/profile/add', 'title' => t('add field'),
Dries's avatar
   
Dries committed
126
127
      'callback' => 'profile_admin_add',
      'type' => MENU_CALLBACK);
128
    $items[] = array('path' => 'admin/settings/profile/edit', 'title' => t('edit field'),
Dries's avatar
   
Dries committed
129
130
      'callback' => 'profile_admin_edit',
      'type' => MENU_CALLBACK);
131
    $items[] = array('path' => 'admin/settings/profile/delete', 'title' => t('delete field'),
Dries's avatar
   
Dries committed
132
133
134
      'callback' => 'profile_admin_delete',
      'type' => MENU_CALLBACK);
  }
135

Dries's avatar
   
Dries committed
136
  return $items;
Dries's avatar
   
Dries committed
137
}
Dries's avatar
   
Dries committed
138

Dries's avatar
   
Dries committed
139
140
141
/**
 * Menu callback; display a list of user information.
 */
Dries's avatar
   
Dries committed
142
function profile_browse() {
Dries's avatar
   
Dries committed
143

Steven Wittens's avatar
Steven Wittens committed
144
  $name = arg(1);
145
  list(,,$value) = explode('/', $_GET['q'], 3);
Dries's avatar
   
Dries committed
146

Steven Wittens's avatar
Steven Wittens committed
147
  $field = db_fetch_object(db_query("SELECT DISTINCT(fid), type, title, page, visibility FROM {profile_fields} WHERE name = '%s'", $name));
Dries's avatar
   
Dries committed
148

Dries's avatar
   
Dries committed
149
  if ($name && $field->fid) {
Steven Wittens's avatar
Steven Wittens committed
150
151
152
153
154
155
    // Do not allow browsing of private fields by non-admins
    if (!user_access('administer users') && $field->visibility == PROFILE_PRIVATE) {
       drupal_access_denied();
       return;
    }

156
    // Compile a list of fields to show
Dries's avatar
   
Dries committed
157
    $fields = array();
158
    $result = db_query('SELECT name, title, type, weight FROM {profile_fields} WHERE fid != %d AND visibility = %d ORDER BY weight', $field->fid, PROFILE_PUBLIC_LISTINGS);
Dries's avatar
   
Dries committed
159
160
161
    while ($record = db_fetch_object($result)) {
      $fields[] = $record;
    }
Dries's avatar
   
Dries committed
162

Dries's avatar
Dries committed
163
    // Determine what query to use:
164
    $arguments = array($field->fid);
Dries's avatar
Dries committed
165
166
167
168
169
    switch ($field->type) {
      case 'checkbox':
        $query = 'v.value = 1';
        break;
      case 'selection':
170
171
        $query = "v.value = '%s'";
        $arguments[] = $value;
Dries's avatar
Dries committed
172
173
        break;
      case 'list':
174
175
        $query = "v.value LIKE '%%%s%%'";
        $arguments[] = $value;
Dries's avatar
Dries committed
176
        break;
Steven Wittens's avatar
Steven Wittens committed
177
178
179
      default:
        drupal_not_found();
        return;
Dries's avatar
Dries committed
180
181
    }

Dries's avatar
   
Dries committed
182
    // Extract the affected users:
183
    $result = pager_query("SELECT u.uid, u.access FROM {users} u INNER JOIN {profile_values} v ON u.uid = v.uid WHERE v.fid = %d AND $query ORDER BY u.access DESC", 20, 0, NULL, $arguments);
Dries's avatar
   
Dries committed
184

Dries's avatar
   
Dries committed
185
    $output = '<div id="profile">';
Dries's avatar
   
Dries committed
186
    while ($account = db_fetch_object($result)) {
187
      $account = user_load(array('uid' => $account->uid));
188
      $fields = _profile_update_user_fields($fields, $account);
189
      $output .= theme('profile_listing', $account, $fields);
Dries's avatar
   
Dries committed
190
191
192
    }
    $output .= theme('pager', NULL, 20);

Dries's avatar
Dries committed
193
    if ($field->type == 'selection' || $field->type == 'list') {
194
      $title = strtr($field->page, array('%value' => theme('placeholder', $value)));
Dries's avatar
   
Dries committed
195
196
    }
    else {
Dries's avatar
   
Dries committed
197
      $title = $field->page;
Dries's avatar
   
Dries committed
198
    }
Dries's avatar
   
Dries committed
199
    $output .= '</div>';
Dries's avatar
   
Dries committed
200

201
    drupal_set_title($title);
Dries's avatar
   
Dries committed
202
    return $output;
Dries's avatar
   
Dries committed
203
  }
Dries's avatar
   
Dries committed
204
  else if ($name && !$field->id) {
Dries's avatar
   
Dries committed
205
    drupal_not_found();
Dries's avatar
   
Dries committed
206
  }
Dries's avatar
   
Dries committed
207
208
209
  else {
    // Compile a list of fields to show
    $fields = array();
210
    $result = db_query('SELECT name, title, type, weight FROM {profile_fields} WHERE visibility = %d ORDER BY category, weight', PROFILE_PUBLIC_LISTINGS);
Dries's avatar
   
Dries committed
211
212
213
214
215
    while ($record = db_fetch_object($result)) {
      $fields[] = $record;
    }

    // Extract the affected users:
216
    $result = pager_query("SELECT uid, access FROM {users} WHERE uid > 0 AND status != 0 ORDER BY access DESC", 20, 0, NULL);
Dries's avatar
   
Dries committed
217
218
219

    $output = '<div id="profile">';
    while ($account = db_fetch_object($result)) {
220
      $account = user_load(array('uid' => $account->uid));
221
      $fields = _profile_update_user_fields($fields, $account);
222
      $output .= theme('profile_listing', $account, $fields);
Dries's avatar
   
Dries committed
223
224
225
226
    }
    $output .= '</div>';
    $output .= theme('pager', NULL, 20);

227
    drupal_set_title(t('user list'));
Dries's avatar
   
Dries committed
228
    return $output;
Dries's avatar
   
Dries committed
229
  }
Dries's avatar
   
Dries committed
230
}
Dries's avatar
   
Dries committed
231

Dries's avatar
   
Dries committed
232
function profile_load_profile(&$user) {
Steven Wittens's avatar
Steven Wittens committed
233
  $result = db_query('SELECT f.name, f.type, v.value FROM {profile_fields} f INNER JOIN {profile_values} v ON f.fid = v.fid WHERE uid = %d', $user->uid);
Dries's avatar
   
Dries committed
234
235
  while ($field = db_fetch_object($result)) {
    if (empty($user->{$field->name})) {
Steven Wittens's avatar
Steven Wittens committed
236
      $user->{$field->name} = _profile_field_serialize($field->type) ? unserialize($field->value) : $field->value;
Dries's avatar
   
Dries committed
237
    }
Dries's avatar
   
Dries committed
238
  }
Dries's avatar
   
Dries committed
239
240
}

241
function profile_save_profile(&$edit, &$user, $category) {
242
  if ($_GET['q'] == 'user/register' || $_GET['q'] == 'admin/user/create') {
243
    $result = db_query('SELECT fid, name, type FROM {profile_fields} WHERE register = 1 AND visibility != %d ORDER BY category, weight', PROFILE_HIDDEN);
Dries's avatar
   
Dries committed
244
245
  }
  else {
246
    $result = db_query("SELECT fid, name, type FROM {profile_fields} WHERE LOWER(category) = LOWER('%s') AND visibility != %d", $category, PROFILE_HIDDEN);
247
    // We use LOWER('%s') instead of PHP's strtolower() to avoid UTF-8 conversion issues.
Dries's avatar
   
Dries committed
248
  }
Dries's avatar
   
Dries committed
249
  while ($field = db_fetch_object($result)) {
Steven Wittens's avatar
Steven Wittens committed
250
251
252
    if (_profile_field_serialize($field->type)) {
       $edit[$field->name] = serialize($edit[$field->name]);
    }
253
254
    db_query("DELETE FROM {profile_values} WHERE fid = %d AND uid = %d", $field->fid, $user->uid);
    db_query("INSERT INTO {profile_values} (fid, uid, value) VALUES (%d, %d, '%s')", $field->fid, $user->uid, $edit[$field->name]);
255
    // Mark field as handled (prevents saving to user->data).
256
    $edit[$field->name] = NULL;
Dries's avatar
   
Dries committed
257
  }
Dries's avatar
   
Dries committed
258
259
}

260
function profile_view_field($user, $field) {
Steven Wittens's avatar
Steven Wittens committed
261
262
263
  // Only allow browsing of private fields for admins
  $browse = user_access('administer users') || $field->visibility != PROFILE_PRIVATE;

264
265
266
  if ($value = $user->{$field->name}) {
    switch ($field->type) {
      case 'textfield':
267
        return check_plain($value);
268
      case 'textarea':
269
        return check_markup($value);
270
      case 'selection':
271
        return $browse ? l($value, 'profile/'. $field->name .'/'. $value) : check_plain($value);
272
      case 'checkbox':
273
        return $browse ? l($field->title, 'profile/'. $field->name) : check_plain($field->title);
274
      case 'url':
275
        return '<a href="'. check_url($value) .'">'. check_plain($value) .'</a>';
Steven Wittens's avatar
Steven Wittens committed
276
277
278
279
280
281
282
283
      case 'date':
        list($format) = explode(' - ', variable_get('date_format_short', 'm/d/Y - H:i'), 2);
        // Note: we avoid PHP's date() because it does not handle dates before
        // 1970 on Windows. This would make the date field useless for e.g.
        // birthdays.
        $replace = array('d' => sprintf('%02d', $value['day']),
                         'j' => $value['day'],
                         'm' => sprintf('%02d', $value['month']),
284
                         'M' => map_month($value['month']),
285
286
287
                         'Y' => $value['year'],
                         'H:i' => null,
                         'g:ia' => null);
Steven Wittens's avatar
Steven Wittens committed
288
        return strtr($format, $replace);
289
      case 'list':
Dries's avatar
   
Dries committed
290
        $values = split("[,\n\r]", $value);
Dries's avatar
Dries committed
291
292
        $fields = array();
        foreach ($values as $value) {
Steven Wittens's avatar
Steven Wittens committed
293
          if ($value = trim($value)) {
294
            $fields[] = $browse ? l($value, "profile/". drupal_urlencode($field->name) ."/". drupal_urlencode($value)) : check_plain($value);
Dries's avatar
Dries committed
295
296
297
          }
        }
        return implode(', ', $fields);
298
299
300
301
    }
  }
}

Dries's avatar
   
Dries committed
302
function profile_view_profile($user) {
Dries's avatar
   
Dries committed
303

304
  profile_load_profile($user);
Dries's avatar
   
Dries committed
305

Steven Wittens's avatar
Steven Wittens committed
306
307
  // Show private fields to administrators and people viewing their own account.
  if (user_access('administer users') || $GLOBALS['user']->uid == $user->uid) {
308
    $result = db_query('SELECT * FROM {profile_fields} WHERE visibility != %d ORDER BY category, weight', PROFILE_HIDDEN);
Steven Wittens's avatar
Steven Wittens committed
309
310
  }
  else {
311
    $result = db_query('SELECT * FROM {profile_fields} WHERE visibility != %d AND visibility != %d ORDER BY category, weight', PROFILE_PRIVATE, PROFILE_HIDDEN);
Steven Wittens's avatar
Steven Wittens committed
312
313
  }

Dries's avatar
   
Dries committed
314
  while ($field = db_fetch_object($result)) {
315
    if ($value = profile_view_field($user, $field)) {
Steven Wittens's avatar
Steven Wittens committed
316
      $description = ($field->visibility == PROFILE_PRIVATE) ? t('The content of this field is private and only visible to yourself.') : '';
317
      $title = ($field->type != 'checkbox') ? check_plain($field->title) : '';
318
319
      $form = array('#title' => $title, '#value' => $value, '#description' => $description);
      $fields[$field->category][$field->name] = theme('item', $form);
Dries's avatar
   
Dries committed
320
321
322
    }
  }

Dries's avatar
Dries committed
323
  return $fields;
Dries's avatar
   
Dries committed
324
}
Dries's avatar
   
Dries committed
325

326
327
function _profile_form_explanation($field) {
  $output = $field->explanation;
Dries's avatar
   
Dries committed
328

329
  if ($field->type == 'list') {
Dries's avatar
   
Dries committed
330
    $output .= ' '. t('Put each item on a separate line or separate them by commas.  No HTML allowed.');
331
332
333
334
335
336
337
338
339
340
341
  }

  if ($field->visibility == PROFILE_PRIVATE) {
    $output .= ' '. t('The content of this field is kept private and will not be shown publicly.');
  }

  return $output;
}

function profile_form_profile($edit, $user, $category) {

342
  if ($_GET['q'] == 'user/register' || $_GET['q'] == 'admin/user/create') {
Dries's avatar
   
Dries committed
343
344
345
    $result = db_query('SELECT * FROM {profile_fields} WHERE register = 1 ORDER BY category, weight');
  }
  else {
346
347
    $result = db_query("SELECT * FROM {profile_fields} WHERE LOWER(category) = LOWER('%s') ORDER BY weight", $category);
    // We use LOWER('%s') instead of PHP's strtolower() to avoid UTF-8 conversion issues.
Dries's avatar
   
Dries committed
348
  }
349

Dries's avatar
   
Dries committed
350
  while ($field = db_fetch_object($result)) {
Dries's avatar
   
Dries committed
351
    $category = $field->category;
352
353
354
    if (!isset($fields[$category])) {
      $fields[$category] = array('#type' => 'fieldset', '#title' => $category, '#weight' => $w++);
    }
Dries's avatar
   
Dries committed
355
356
    switch ($field->type) {
      case 'textfield':
357
      case 'url':
358
        $fields[$category][$field->name] = array('#type' => 'textfield', '#title' => check_plain($field->title), '#default_value' => $edit[$field->name], '#maxlength' => 255, '#description' => _profile_form_explanation($field), '#required' => $field->required);
Dries's avatar
   
Dries committed
359
        break;
360
      case 'textarea':
361
        $fields[$category][$field->name] = array('#type' => 'textarea', '#title' => check_plain($field->title), '#default_value' => $edit[$field->name], '#description' => _profile_form_explanation($field), '#required' => $field->required);
Dries's avatar
Dries committed
362
363
        break;
      case 'list':
364
        $fields[$category][$field->name] = array('#type' => 'textarea', '#title' => check_plain($field->title), '#default_value' => $edit[$field->name], '#description' => _profile_form_explanation($field), '#required' => $field->required);
Dries's avatar
   
Dries committed
365
        break;
366
      case 'checkbox':
367
        $fields[$category][$field->name] = array('#type' => 'checkbox', '#title' => check_plain($field->title), '#default_value' => $edit[$field->name], '#description' => _profile_form_explanation($field), '#required' => $field->required);
Dries's avatar
   
Dries committed
368
369
370
        break;
      case 'selection':
        $options = array('--');
Dries's avatar
   
Dries committed
371
        $lines = split("[,\n\r]", $field->options);
Dries's avatar
   
Dries committed
372
373
374
375
376
        foreach ($lines as $line) {
          if ($line = trim($line)) {
            $options[$line] = $line;
          }
        }
377
        $fields[$category][$field->name] = array('#type' => 'select', '#title' => check_plain($field->title), '#default_value' => $edit[$field->name], '#options' => $options, '#description' => _profile_form_explanation($field), '#required' => $field->required);
Dries's avatar
   
Dries committed
378
        break;
Steven Wittens's avatar
Steven Wittens committed
379
      case 'date':
380
        $fields[$category][$field->name] = array('#type' => 'date', '#title' => check_plain($field->title), '#default_value' => $edit[$field->name], '#description' => _profile_form_explanation($field), '#required' => $field->required);
Steven Wittens's avatar
Steven Wittens committed
381
        break;
Dries's avatar
   
Dries committed
382
383
    }
  }
384
  return $fields;
Dries's avatar
   
Dries committed
385
386
}

387
388
389
/**
 * Helper function: update an array of user fields by calling profile_view_field
 */
390
function _profile_update_user_fields($fields, $account) {
391
392
393
394
395
  foreach ($fields as $key => $field) {
    if ($value = profile_view_field($account, $field)) {
      $fields[$key]->value = $value;
    }
  }
396
  return $fields;
397
398
}

399
function profile_validate_profile($edit, $category) {
Dries's avatar
   
Dries committed
400

401
  if ($_GET['q'] == 'user/register' || $_GET['q'] == 'admin/user/create') {
Dries's avatar
   
Dries committed
402
403
404
    $result = db_query('SELECT * FROM {profile_fields} WHERE register = 1 ORDER BY category, weight');
  }
  else {
405
406
    $result = db_query("SELECT * FROM {profile_fields} WHERE LOWER(category) = LOWER('%s') ORDER BY weight", $category);
    // We use LOWER('%s') instead of PHP's strtolower() to avoid UTF-8 conversion issues.
Dries's avatar
   
Dries committed
407
  }
408
409

  while ($field = db_fetch_object($result)) {
410
    if ($edit[$field->name]) {
Dries's avatar
   
Dries committed
411
412
      if ($field->type == 'url') {
        if (!valid_url($edit[$field->name], true)) {
413
414
          form_set_error($field->name, t('The value provided for %field is not a valid URL.', array('%field' => theme('placeholder', $field->title))));
        }
415
416
      }
    }
417
    else if ($field->required && !user_access('administer users')) {
418
      form_set_error($field->name, t('The field %field is required.', array('%field' => theme('placeholder', $field->title))));
Dries's avatar
   
Dries committed
419
    }
420
421
422
423
424
  }

  return $edit;
}

425
426
427
function profile_categories() {
  $result = db_query("SELECT DISTINCT(category) FROM {profile_fields}");
  while ($category = db_fetch_object($result)) {
428
    $data[] = array('name' => check_plain($category->category), 'title' => $category->category, 'weight' => 3);
429
430
431
432
  }
  return $data;
}

Dries's avatar
   
Dries committed
433
434
435
/**
 * Implementation of hook_user().
 */
436
function profile_user($type, &$edit, &$user, $category = NULL) {
Dries's avatar
   
Dries committed
437
438
439
  switch ($type) {
    case 'load':
      return profile_load_profile($user);
Dries's avatar
   
Dries committed
440
441
    case 'register':
      return profile_form_profile($edit, $user, $category);
Dries's avatar
   
Dries committed
442
    case 'update':
443
    case 'insert':
444
      return profile_save_profile($edit, $user, $category);
Dries's avatar
   
Dries committed
445
446
    case 'view':
      return profile_view_profile($user);
447
    case 'form':
448
      return profile_form_profile($edit, $user, $category);
Dries's avatar
   
Dries committed
449
    case 'validate':
450
451
452
      return profile_validate_profile($edit, $category);
    case 'categories':
      return profile_categories();
Dries's avatar
   
Dries committed
453
454
  }
}
Dries's avatar
   
Dries committed
455

Dries's avatar
   
Dries committed
456
function profile_validate_form($edit) {
Dries's avatar
   
Dries committed
457

Dries's avatar
   
Dries committed
458
459
  // Validate the title:
  if (!$edit['title']) {
Dries's avatar
   
Dries committed
460
    form_set_error('title', t('You must enter a title.'));
Dries's avatar
   
Dries committed
461
462
  }

Dries's avatar
   
Dries committed
463
464
  // Validate the 'form name':
  if (eregi('[^a-z0-9_-]', $edit['name'])) {
Dries's avatar
   
Dries committed
465
    form_set_error('name', t('The specified form name contains one or more illegal characters.  Spaces or any other special characters expect dash (-) and underscore (_) are not allowed.'));
Dries's avatar
   
Dries committed
466
467
  }

Dries's avatar
   
Dries committed
468
  if (in_array($edit['name'], user_fields())) {
Dries's avatar
   
Dries committed
469
    form_set_error('name', t('The specified form name is reserved for use by Drupal.'));
Dries's avatar
   
Dries committed
470
471
  }

Dries's avatar
   
Dries committed
472
473
  // Validate the category:
  if (!$edit['category']) {
Dries's avatar
   
Dries committed
474
    form_set_error('category', t('You must enter a category.'));
Dries's avatar
   
Dries committed
475
  }
476
477
478
479

  if ($edit['category'] == 'account') {
    form_set_error('category', t('The specified category name is reserved for use by Drupal.'));
  }
Dries's avatar
   
Dries committed
480
481
}

Dries's avatar
   
Dries committed
482
483
484
/**
 * Menu callback; adds a new field to all user profiles.
 */
Dries's avatar
   
Dries committed
485
486
487
function profile_admin_add($type) {
  if ($_POST['op']) {
    $data = $_POST['edit'];
Dries's avatar
   
Dries committed
488

Dries's avatar
   
Dries committed
489
490
491
    // Validate the form:
    profile_validate_form($data);

492
    if (db_result(db_query("SELECT fid FROM {profile_fields} WHERE title = '%s' AND category = '%s'", $data['title'], $data['category']))) {
Steven Wittens's avatar
Steven Wittens committed
493
      form_set_error('title', t('The specified title is already in use.'));
494
    }
Dries's avatar
   
Dries committed
495
496

    if (db_result(db_query("SELECT fid FROM {profile_fields} WHERE name = '%s'", $data['name']))) {
Steven Wittens's avatar
Steven Wittens committed
497
      form_set_error('name', t('The specified name is already in use.'));
498
    }
Dries's avatar
   
Dries committed
499

Dries's avatar
   
Dries committed
500
    if (!form_get_errors()) {
Dries's avatar
   
Dries committed
501
      db_query("INSERT INTO {profile_fields} (title, name, explanation, category, type, weight, required, register, visibility, options, page) VALUES ('%s', '%s', '%s', '%s', '%s', %d, %d, %d, %d, '%s', '%s')", $data['title'], $data['name'], $data['explanation'], $data['category'], $type, $data['weight'], $data['required'], $data['register'], $data['visibility'], $data['options'], $data['page']);
Dries's avatar
   
Dries committed
502

Dries's avatar
   
Dries committed
503
504
      cache_clear_all();

Steven Wittens's avatar
Steven Wittens committed
505
      drupal_set_message(t('The field has been created.'));
506
      drupal_goto('admin/settings/profile');
Dries's avatar
   
Dries committed
507
    }
Dries's avatar
   
Dries committed
508
  }
Dries's avatar
   
Dries committed
509
510
511
512
  else {
    $data = array('name' => 'profile_');
  }

513
  drupal_set_title(t('Add new %type', array('%type' => _profile_field_types($type))));
Dries's avatar
   
Dries committed
514
  return _profile_field_form($type, $data);
Dries's avatar
   
Dries committed
515
516
}

Dries's avatar
   
Dries committed
517
518
519
/**
 * Menu callback; displays the profile field editing form.
 */
Dries's avatar
   
Dries committed
520
function profile_admin_edit($fid) {
Dries's avatar
   
Dries committed
521

Dries's avatar
   
Dries committed
522
523
  if ($_POST['op']) {
    $data = $_POST['edit'];
Dries's avatar
   
Dries committed
524

Dries's avatar
   
Dries committed
525
526
    // Validate form:
    profile_validate_form($data);
Dries's avatar
   
Dries committed
527

Dries's avatar
   
Dries committed
528
    if (!form_get_errors()) {
Dries's avatar
   
Dries committed
529
      db_query("UPDATE {profile_fields} SET title = '%s', name = '%s', explanation = '%s', category = '%s', weight = %d, required = %d, register = %d, visibility = %d, options = '%s', page = '%s' WHERE fid = %d", $data['title'], $data['name'], $data['explanation'], $data['category'], $data['weight'], $data['required'], $data['register'], $data['visibility'], $data['options'], $data['page'], $fid);
Dries's avatar
   
Dries committed
530

Dries's avatar
   
Dries committed
531
532
      cache_clear_all();

Steven Wittens's avatar
Steven Wittens committed
533
      drupal_set_message(t('The field has been updated.'));
534
      drupal_goto('admin/settings/profile');
Dries's avatar
   
Dries committed
535
    }
Dries's avatar
   
Dries committed
536
537
  }
  else {
Dries's avatar
   
Dries committed
538
    $data = db_fetch_array(db_query('SELECT * FROM {profile_fields} WHERE fid = %d', $fid));
Dries's avatar
   
Dries committed
539
540
  }

541
  drupal_set_title(t('Edit %type', array('%type' => $data['type'])));
Dries's avatar
   
Dries committed
542
  return _profile_field_form($data['type'], $data);
Dries's avatar
   
Dries committed
543
544
}

Dries's avatar
   
Dries committed
545
546
547
/**
 * Menu callback; deletes a field from all user profiles.
 */
Dries's avatar
   
Dries committed
548
function profile_admin_delete($fid) {
549
550
551
  $field = db_fetch_object(db_query("SELECT title FROM {profile_fields} WHERE fid = %d", $fid));
  if ($_POST['edit']['confirm']) {
    db_query('DELETE FROM {profile_fields} WHERE fid = %d', $fid);
552
    db_query('DELETE FROM {profile_values} WHERE fid = %d', $fid);
553
554
555
556
557
    cache_clear_all();
    drupal_set_message(t('The field %field has been deleted.', array('%field' => theme('placeholder', $field->title))));
    drupal_goto('admin/settings/profile');
  }
  else {
558
559
560
561
562
563
    return confirm_form('profile_confirm_delete', $form,
                        t('Are you sure you want to delete the field %field?', array('%field' => theme('placeholder', $field->title))),
                        'admin/settings/profile',
                        t('This action cannot be undone. If users have entered values into this field in their profile, these entries will also be deleted. If you want to keep the user-entered data, instead of deleting the field you may wish to <a href="%edit-field">edit this field</a> and change it to a \'hidden profile field\' so that it may only be accessed by administrators.', array('%edit-field' => url('admin/settings/profile/edit/' . $fid))),
                        t('Delete'),
                        t('Cancel'));
564
  }
Dries's avatar
   
Dries committed
565
566
}

Dries's avatar
   
Dries committed
567
function _profile_field_form($type, $edit = array()) {
568

569
  $form['fields'] = array('#type' => 'fieldset', '#title' => t('Field settings'));
570
571
572
  $form['fields']['category'] = array('#type' => 'textfield', '#title' => t('Category'), '#default_value' => $edit['category'], '#description' => t('The category the new field should be part of.  Categories are used to group fields logically.  An example category is "Personal information".'));
  $form['fields']['title'] = array('#type' => 'textfield', '#title' => t('Title'), '#default_value' => $edit['title'], '#description' => t('The title of the new field.  The title will be shown to the user.  An example title is "Favorite color".'));
  $form['fields']['name'] = array('#type' => 'textfield', '#title' => t('Form name'), '#default_value' => $edit['name'], '#description' => t('The name of the field.  The form name is not shown to the user but used internally in the HTML code and URLs.
Dries's avatar
   
Dries committed
573
Unless you know what you are doing, it is highly recommended that you prefix the form name with <code>profile_</code> to avoid name clashes with other fields.  Spaces or any other special characters except dash (-) and underscore (_) are not allowed. An example name is "profile_favorite_color" or perhaps just "profile_color".'));
574
  $form['fields']['explanation'] = array('#type' => 'textarea', '#title' => t('Explanation'), '#default_value' => $edit['explanation'], '#description' => t('An optional explanation to go with the new field.  The explanation will be shown to the user.'));
Dries's avatar
   
Dries committed
575
  if ($type == 'selection') {
576
    $form['fields']['options'] = array('#type' => 'textarea', '#title' => t('Selection options'), '#default_value' => $edit['options'], '#description' => t('A list of all options.  Put each option on a separate line.  Example options are "red", "blue", "green", etc.'));
Dries's avatar
   
Dries committed
577
  }
578
579
  $form['fields']['weight'] = array('#type' => 'weight', '#title' => t('Weight'), '#default_value' => $edit['weight'], '#delta' => 5, '#description' =>  t('The weights define the order in which the form fields are shown.  Lighter fields "float up" towards the top of the category.'));
  $form['fields']['visibility'] = array('#type' => 'radios', '#title' => t('Visibility'), '#default_value' => $edit['visibility'], '#options' => array(PROFILE_HIDDEN => t('Hidden profile field, only accessible by administrators, modules and themes.'), PROFILE_PRIVATE => t('Private field, content only available to privileged users.'), PROFILE_PUBLIC => t('Public field, content shown on profile page but not used on member list pages.'), PROFILE_PUBLIC_LISTINGS => t('Public field, content shown on profile page and on member list pages.')));
Dries's avatar
Dries committed
580
  if ($type == 'selection' || $type == 'list') {
581
    $form['fields']['page'] = array('#type' => 'textfield', '#title' => t('Page title'), '#default_value' => $edit['page'], '#description' => t('The title of the page showing all users with the specified field.  The word <code>%value</code> will be substituted with the corresponding value.  An example page title is "People whose favorite color is %value".  Only applicable if the field is configured to be shown on member list pages.'));
Dries's avatar
   
Dries committed
582
583
  }
  else {
584
    $form['fields']['page'] = array('#type' => 'textfield', '#title' => t('Page title'), '#default_value' => $edit['page'], '#description' => t('The title of the page showing all users with the specified field.  Only applicable if the field is configured to be shown on member listings.'));
Dries's avatar
   
Dries committed
585
  }
586
587
  $form['fields']['required'] = array('#type' => 'checkbox', '#title' => t('The user must enter a value.'), '#default_value' => $edit['required']);
  $form['fields']['register'] = array('#type' => 'checkbox', '#title' => t('Visible in user registration form.'), '#default_value' => $edit['register']);
588
  $form['submit'] = array('#type' => 'submit', '#value' => t('Save field'));
Dries's avatar
   
Dries committed
589

590
  return drupal_get_form('_profile_field_form', $form);
Dries's avatar
   
Dries committed
591
592
}

Dries's avatar
   
Dries committed
593
594
595
/**
 * Menu callback; display a listing of all editable profile fields.
 */
Dries's avatar
   
Dries committed
596
597
598
function profile_admin_overview() {

  $result = db_query('SELECT * FROM {profile_fields} ORDER BY category, weight');
Steven Wittens's avatar
Steven Wittens committed
599
  $rows = array();
Dries's avatar
   
Dries committed
600
  while ($field = db_fetch_object($result)) {
601
    $rows[] = array(check_plain($field->title), $field->name, _profile_field_types($field->type), $field->category, l(t('edit'), "admin/settings/profile/edit/$field->fid"), l(t('delete'), "admin/settings/profile/delete/$field->fid"));
Steven Wittens's avatar
Steven Wittens committed
602
603
604
  }
  if (count($rows) == 0) {
    $rows[] = array(array('data' => t('No fields defined.'), 'colspan' => '6'));
Dries's avatar
   
Dries committed
605
  }
Dries's avatar
   
Dries committed
606

Dries's avatar
   
Dries committed
607
  $header = array(t('Title'), t('Name'), t('Type'), t('Category'), array('data' => t('Operations'), 'colspan' => '2'));
Dries's avatar
   
Dries committed
608
609

  $output  = theme('table', $header, $rows);
Steven Wittens's avatar
Steven Wittens committed
610
  $output .= '<h2>'. t('Add new field') .'</h2>';
Dries's avatar
   
Dries committed
611
612
  $output .= '<ul>';
  foreach (_profile_field_types() as $key => $value) {
613
    $output .= '<li>'. l($value, "admin/settings/profile/add/$key") .'</li>';
Dries's avatar
   
Dries committed
614
  }
Dries's avatar
   
Dries committed
615
616
  $output .= '</ul>';

Dries's avatar
   
Dries committed
617
  return $output;
Dries's avatar
   
Dries committed
618
619
}

620
function theme_profile_block($account, $fields = array()) {
621

622
  $output .= theme('user_picture', $account);
623
624

  foreach ($fields as $field) {
625
    if ($field->value) {
626
      $output .= "<p><strong>$field->title:</strong><br />$field->value</p>\n";
627
628
629
630
631
632
    }
  }

  return $output;
}

633
function theme_profile_listing($account, $fields = array()) {
Dries's avatar
   
Dries committed
634
635

  $output  = "<div class=\"profile\">\n";
636
637
  $output .= theme('user_picture', $account);
  $output .= ' <div class="name">'. theme('username', $account) ."</div>\n";
Dries's avatar
   
Dries committed
638
639

  foreach ($fields as $field) {
640
    if ($field->value) {
641
      $output .= " <div class=\"field\">$field->value</div>\n";
Dries's avatar
   
Dries committed
642
643
    }
  }
Dries's avatar
   
Dries committed
644
645
646
647
648
649
650

  $output .= "</div>\n";

  return $output;
}

function _profile_field_types($type = NULL) {
Steven Wittens's avatar
Steven Wittens committed
651
652
653
654
655
656
657
  $types = array('textfield' => t('single-line textfield'),
                 'textarea' => t('multi-line textfield'),
                 'checkbox' => t('checkbox'),
                 'selection' => t('list selection'),
                 'list' => t('freeform list'),
                 'url' => t('URL'),
                 'date' => t('date'));
Dries's avatar
   
Dries committed
658
  return isset($type) ? $types[$type] : $types;
Dries's avatar
   
Dries committed
659
660
}

Steven Wittens's avatar
Steven Wittens committed
661
662
663
664
function _profile_field_serialize($type = NULL) {
  return $type == 'date';
}

665